The SideWinder APT group has intensified espionage operations across South Asia, targeting government, military, and public-sector entities in countries including Sri Lanka, Bangladesh, and Pakistan. Researchers reported spear-phishing campaigns using malicious Word and RTF documents that exploited CVE-2017-0199 and CVE-2017-11882, alongside geofenced delivery, shellcode loaders, server-side polymorphism, and DLL sideloading to limit payloads to intended victims and evade analysis. Confirmed targets included the Central Bank of Sri Lanka and the Sri Lanka Army’s 55th Division Battalion, with infrastructure such as army-govbd[.]info supporting multi-stage infections that ultimately deployed StealerBot for credential theft, reconnaissance, persistence, and data exfiltration.
Separate reporting tied SideWinder to a newer Pakistan-focused campaign delivering a backdoor called WarHawk through malicious ISO files hosted on Pakistan’s National Electric Power Regulatory Authority website and lures copied from legitimate Cabinet Division advisories. WarHawk profiled infected systems, executed commands, enumerated files, and transferred additional payloads, including a custom Cobalt Strike loader that used KernelCallbackTable injection and a Pakistan Standard Time check to constrain execution. Earlier research also linked SideWinder to Android spyware distributed through Google Play as fake VPN, cleaning, and religious apps, showing the group’s broader use of mobile and desktop malware, reused infrastructure, and regionally tailored delivery to sustain long-running intelligence collection in South Asia.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
A representative malicious document named "Caution Against Propaganda and Misinformation Campaigns.docx" was uploaded to VirusTotal from Bangladesh. Acronis linked the sample to SideWinder's South Asia espionage campaign and its exploit chain using CVE-2017-0199.
Acronis confirmed phishing emails explicitly addressed to the Central Bank of Sri Lanka and the Sri Lanka Army's 55th Division Battalion. The targeting formed part of the broader 2025 SideWinder espionage activity in South Asia.
Acronis attributed a 2025 espionage campaign to SideWinder targeting government and military institutions in Sri Lanka, Bangladesh, and Pakistan. The operation used spear-phishing emails with tailored Word and RTF lures exploiting CVE-2017-0199 and CVE-2017-11882.
Acronis observed a surge of new or repointed SideWinder infrastructure domains in early 2025, including army-govbd[.]info. The infrastructure supported staged payload delivery and geofenced access controls.
QiAnXin reported that SideWinder-linked Android apps masquerading as tools such as Secure VPN, Z Cleaner, and religious-themed apps had been removed from Google Play by June 5, 2022. The apps had reportedly accumulated more than 1,000 installs before removal.
Multiple reports describe SideWinder as an espionage-focused APT group active since at least 2012, with long-running targeting across South Asia. This historical anchor appears in both the Android and WarHawk reporting.
Zscaler observed WarHawk downloading second-stage payloads including Snitch.exe, OneDrive.exe, and DDRA.exe from its C2 infrastructure. One payload acted as a custom Cobalt Strike loader using anti-analysis checks and KernelCallbackTable injection to deploy a beacon.
Zscaler found SideWinder ISO lures including 32-Advisory-No-32.iso and 33-Advisory-No-33-2022.pdf.iso hosted on nepra[.]org[.]pk. The hosting suggested a possible compromise of the Pakistan National Electric Power Regulatory Authority web server.
Zscaler ThreatLabz reported a new SideWinder backdoor named WarHawk used in espionage operations targeting Pakistan. The campaign used malicious ISO files with LNK launchers and decoy PDFs themed on Pakistani government advisories.
QiAnXin documented a suspected SideWinder Android campaign using Google Play-hosted apps to target South Asia. The malware obtained C2 information through install_referrer data, hardcoded URLs, or Firebase, then beaconed host data and downloaded plugins every 10 minutes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceacronis.com
Open sourceti.qianxin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.